Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-6051 | 3 Debian, Google, Redhat | 5 Debian Linux, Chrome, Enterprise Linux Desktop and 2 more | 2018-11-15 | 4.3 MEDIUM | 4.3 MEDIUM |
XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page. | |||||
CVE-2018-17053 | 1 Progress | 1 Sitefinity Cms | 2018-11-15 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17054. | |||||
CVE-2018-17056 | 1 Progress | 1 Sitefinity Cms | 2018-11-15 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-17054 | 1 Progress | 1 Sitefinity Cms | 2018-11-15 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17053. | |||||
CVE-2018-17556 | 1 Modx | 1 Modx Revolution | 2018-11-15 | 3.5 LOW | 5.4 MEDIUM |
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action. | |||||
CVE-2018-15606 | 1 Salesagility | 1 Suitecrm | 2018-11-15 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message. | |||||
CVE-2018-17832 | 1 Wuzhicms | 1 Wuzhi Cms | 2018-11-15 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter. | |||||
CVE-2018-16277 | 1 Xwiki | 1 Xwiki | 2018-11-15 | 3.5 LOW | 5.4 MEDIUM |
The Image Import function in XWiki through 10.7 has XSS. | |||||
CVE-2009-4608 | 1 Canon-its | 1 Accessguardian | 2018-11-15 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Canon IT Solutions Inc. ACCESSGUARDIAN 3.0.14 and earlier, and 3.5.6 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to authentication. | |||||
CVE-2018-17369 | 1 Springboot Authority Project | 1 Springboot Authority | 2018-11-15 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in springboot_authority through 2017-03-06. There is stored XSS via the admin/role/edit roleKey, name, or description parameter. | |||||
CVE-2018-17574 | 1 Ymfe | 1 Yapi | 2018-11-14 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project. | |||||
CVE-2015-9270 | 1 Theholidaycalendar | 1 Holiday Calendar | 2018-11-14 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in the the-holiday-calendar plugin before 1.11.3 for WordPress via the thc-month parameter. | |||||
CVE-2018-16779 | 1 Blogcms Project | 1 Blogcms | 2018-11-13 | 4.3 MEDIUM | 6.1 MEDIUM |
BlogCMS through 2016-10-25 has XSS via a comment. | |||||
CVE-2018-17320 | 1 Ucms Project | 1 Ucms | 2018-11-13 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action. | |||||
CVE-2018-16147 | 1 Opsview | 1 Opsview | 2018-11-13 | 4.3 MEDIUM | 6.1 MEDIUM |
The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting. | |||||
CVE-2018-16148 | 1 Opsview | 1 Opsview | 2018-11-13 | 4.3 MEDIUM | 6.1 MEDIUM |
The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting. | |||||
CVE-2018-0642 | 1 Foliovision | 1 Fv Flowplayer Video Player | 2018-11-13 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-17361 | 1 Weaselcms Project | 1 Weaselcms | 2018-11-09 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple XSS vulnerabilities in WeaselCMS v0.3.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php because $_SERVER['PHP_SELF'] is mishandled. | |||||
CVE-2018-4133 | 3 Apple, Canonical, Webkitgtk | 3 Safari, Ubuntu Linux, Webkitgtk\+ | 2018-11-09 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |||||
CVE-2018-17002 | 1 Ricoh | 2 Mp 2001sp, Mp 2001sp Firmware | 2018-11-09 | 4.3 MEDIUM | 6.1 MEDIUM |
On the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi. |